Some ransomware rings have started stealing data before they encrypt to use stolen data as leverage, ensuring that even victims with backups make the payment
Ransomware operators stealing data before they encrypt means backups are not enough. — Not every ransomware attack is an unmitigated disaster.
Context & Ripple Effects
This story closes the loop on an escalation that began years ago, when skilled attackers started using evolved crypto-ransomware to turn every network intrusion into a potential payday (every intrusion a payday). The new wrinkle reported here is sequencing: exfiltration before encryption, so the stolen copy itself becomes the hostage.
That move lands on an ecosystem already primed to pay. ProPublica found US data recovery firms marketing 'hi-tech' decryption while quietly just paying ransoms and marking up the bill (recovery firms that paid ransoms), and cyber insurers often preferring to settle in ransom even when backups could restore files, to save claim costs (insurers preferring to pay). Exfiltration-first tactics make those payment paths harder to avoid.
First-order effects
- Victims with verified backups lose their main escape hatch: restoring systems no longer undoes the breach, because the stolen data can still be published or sold if they refuse to pay.
- Cyber insurers and incident responders face a changed negotiation — the insurer's cost-saving preference for paying ransoms now applies even to clients whose backup posture would previously have argued for restoration instead.
Second-order effects
- Data recovery firms that resell ransom payments as 'decryption services' take on added exposure, since a successful file restore no longer ends the victim's crisis and the firm's promise of resolution becomes harder to sell.
- Security tooling built around detecting encryption's heavy file I/O misses the quieter exfiltration phase that precedes it — a gap later exploited by gangs using intermittent encryption to evade exactly those detectors (intermittent encryption evading detection).
Third-order effects
- If the pattern holds, ransomware stops being purely an availability problem and becomes a data-breach problem, pulling every attack into breach-notification, disclosure, and regulatory territory regardless of whether systems are restored.
- The economics of extortion shift from 'how good are your backups' to 'how much is your data worth public,' which pressures buyers toward prevention and egress monitoring rather than recovery — reshaping what cyber insurance underwrites and what security budgets prioritize.
The trend: Ransomware is evolving from single-leverage encryption into layered extortion where stolen data, not locked files, is the primary collateral — making payment pressure independent of victims' recovery capability.